Researchers reported that the AngrySpark Windows backdoor, previously observed on a single UK victim, used a highly engineered three-stage architecture built around a custom virtual machine running inside svchost.exe. The malware employed a masquerading DLL loader, a VM-based shellcode loader, and a beacon that profiled the host, fetched encrypted payloads from command-and-control servers, and hid HTTPS traffic as PNG image requests. Analysis of memory snapshots from 2022 through early 2023 showed the implant was actively maintained before development appeared to stop, and the operation faded as its infrastructure lapsed, with blocked C2 connectivity, expired domains, and expired certificates effectively ending the malware’s activity.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-27, Bill Marczak published an analysis arguing that AngrySpark infrastructure overlaps with the previously tracked SCALENE cluster and discussing possible relationships to OBTUSE and Operation Triangulation. The article stopped short of definitive attribution but presented the overlap as a significant clue about the spyware's pedigree.
A later analysis reported that a server previously tracked as part of the SCALENE cluster was confirmed by Gen in April 2026 as an AngrySpark command-and-control server. This connected SCALENE to real spyware activity and suggested infrastructure overlap with other suspected spyware clusters.
On 2026-04-14, Gen Digital published research detailing the AngrySpark malware, its architecture, and its observed operational timeline. The report described the malware as highly sophisticated but seen on only one host.
By June 2023, the DLL certificate associated with AngrySpark had expired, effectively contributing to the malware's disappearance. Gen Digital described this as part of the operation's end state.
By May 2023, the beacon domain used by AngrySpark had expired. This further degraded the malware's ability to operate.
By April 2023, the malware's command-and-control connection was blocked. Gen Digital cited this as part of the infrastructure's decline and the malware's disappearance.
Analysis of a January 2023 memory snapshot suggested AngrySpark's code had frozen by then, with only configuration changes continuing afterward. This marked a shift from earlier active maintenance.
A June 2022 memory snapshot indicated the malware was still being actively maintained in mid-2022. Gen Digital said analysis showed active maintenance during this period.
One of the analyzed memory snapshots from May 2022 showed AngrySpark active on the victim host. Gen Digital used this snapshot as part of its reconstruction of the malware's development and operation.
Gen Digital reported discovering the AngrySpark backdoor on a single victim machine in the United Kingdom in spring 2022. The malware used a modular three-stage architecture including a DLL loader, a VM-based shellcode loader, and a beacon payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcegendigital.com
Open sourcedatatracker.ietf.org
Open sourcedatatracker.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.